CVE-2025-49088: Input Validation
Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pexip Infinityto a version that resolves this vulnerability.Fixed in 37.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49088?
CVE-2025-49088 is considered a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2025-49088?
To mitigate CVE-2025-49088, upgrade your Pexip Infinity software to version 37.2 or later.
What does CVE-2025-49088 affect?
CVE-2025-49088 affects Pexip Infinity versions 32.0 through 37.1 in certain configurations of the One Touch Join service.
What is the impact of CVE-2025-49088?
CVE-2025-49088 allows remote attackers to trigger a software abort, resulting in a denial of service.
Is CVE-2025-49088 easy to exploit?
Yes, CVE-2025-49088 can be easily exploited by sending a specially crafted calendar invite.